Zoom Communications, Inc.

First CVE: Sep 27, 2021Active for: 5 years
226
CVEs Published
More CVEs Published than 81% of tracked CNAs
37.7
Avg CVEs / Year
More Avg CVEs / Year than 80% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Zoom Communications, Inc. as a CNA, 94.2% affect products that Zoom Communications, Inc. develops as a vendor.

94.2%
Self-reported: 213Third-party: 13

Of all the CVEs published that affect products developed by Zoom Communications, Inc., 91.8% are self-published by Zoom Communications, Inc. as a CNA.

91.8%
Self-published: 213Published by other CNAs: 19

Trends Over Time

The number and severity of CVEs published by Zoom Communications, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2021
4 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

Top CVEs

All CVEs published by Zoom Communications, Inc. as a CNA, regardless of affected vendor or product.

226 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account
Jul 16, 20269.849NONO
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via n
Jan 20, 20269.944NONO
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an
Jun 12, 20269.839NONO
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to
Jul 16, 20267.837NONO
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
Jul 16, 20267.837NONO
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to
Jul 16, 20267.035NONO
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Nov 13, 20259.835NONO
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via net
Mar 11, 20269.834NONO
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber
Nov 24, 20219.834NONO
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
Aug 12, 20258.833NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA226 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local81 (35.8%)
Network139 (61.5%)
Unknown0 (0.0%)
Physical1 (0.4%)
Adjacent Network5 (2.2%)
Attack Complexity
Low214 (94.7%)
High12 (5.3%)
Unknown0 (0.0%)
User Interaction
None187 (82.7%)
Unknown0 (0.0%)
Required39 (17.3%)
Privileges Required
Low137 (60.6%)
High14 (6.2%)
None75 (33.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (226 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Zoom Communications, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Zoom Communications, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs